PT-2026-63337 · Red Hat · Red Hat Ansible Automation Platform 2

CVE-2026-16544

·

Publicado

2026-07-22

·

Atualizado

2026-07-22

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
A flaw was found in AWX. The websocket event consumer performs RBAC authorization checks only for event groups that are mapped in the consumer access() function (job events, workflow events, ad hoc command events). Three event groups - inventory update events, project update events, and system job events — are not mapped, causing the authorization check to be skipped. Any authenticated user can subscribe to these unmapped websocket event groups for any object ID and receive real-time stdout output from jobs belonging to organizations they have no access to. This is an incomplete remediation of CVE-2020-10698.

Correção

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-16544

Produtos afetados

Red Hat Ansible Automation Platform 2